Cybersecurity 5 min read

A Third Citrix NetScaler Flaw Hit Appliances That Had Installed Last Week's Emergency Fix

CVE-2026-88779 affects boxes that use SAML sign-in. Citrix calls it a crash; a researcher found malware running on a patched honeypot. Patch again, then check the logs.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 5 Oct 2026, 12:22 PM (SGT)
Share:
Network equipment in a rack with patch cables connected Network equipment in a rack with patch cables connected Photo by Tho-Ge on Pixabay
Advertisement

5 OCT 2026 — A week after Citrix rushed out fixes for two NetScaler flaws already under attack, a third was being exploited on appliances that had installed them. Citrix released new builds on 4 October for CVE-2026-88779, a memory flaw in how NetScaler handles SAML sign-in requests. Administrators who patched last week have to patch again if their appliances use SAML.

Citrix describes the flaw as a crash that knocks the service offline. A researcher watching his own patched test machines says one later ran a downloaded malware binary.

What Citrix has confirmed

The CVE record, published by NetScaler on 4 October, titles the flaw "Memory overflow vulnerability leading to Denial of Service" and scores it 8.7 on version 4 of the severity scale, with an impact on availability only. It affects NetScaler ADC and NetScaler Gateway. Fixed builds are 14.1-73.41 and 13.1-64.28, 14.1-73.41 FIPS, and 13.1-37.282 for the FIPS and NDcPP versions.

Only appliances using SAML authentication with Gateway or AAA are exposed, whether the box is the service provider or the identity provider. Citrix's guidance tells customers to search their configuration for add authentication samlAction or add authentication samlIdPProfile.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the guidance says. Repeated triggering can keep the service down, and Citrix says it has "not identified an impact on the integrity of customer data."

8.7Severity score, rated for availability impact only
2 OctPatched test appliances first seen crashing
4 OctFixed builds released and flaw added to CISA's catalogue
7 OctDeadline for US federal agencies, with forensic triage required

Patched last week, exposed this week

The fixes Citrix shipped on 27 September for CVE-2026-88771 and CVE-2026-88772 were builds 14.1-73.37 and 13.1-64.23. Those versions are vulnerable to the new flaw, and Citrix's guidance says anyone who installed them and uses SAML should "upgrade your deployment again".

For appliances that cannot be upgraded at once, Citrix offers deny-list signatures delivered through NetScaler Console. They apply only to builds from 14.1-73.37 up to the fix and from 13.1-64.23 up to the fix, the same range administrators moved to last week.

Crash, or code execution?

Kevin Beaumont, a security researcher who runs NetScaler honeypots, posted on 2 October that his patched 13.1 and 14.1 test appliances were crashing, with requests from several source addresses. Minutes later he wrote that "on one of the honeypots it's running a downloaded (malware) binary," adding that both machines were patched.

On 4 October he noted that the "denial of service" label matches the one given to CVE-2025-6543, a NetScaler flaw that was later used for remote code execution in real attacks. He also wrote that more than one group was involved, and that one "wasn't trying to crash services."

Advertisement

BleepingComputer reported that crafted SAML requests carried shell commands fetching payloads from 213.209.159[.]55. It also reported that watchTowr Labs said it had reproduced the vulnerability. Citrix has not said whether the flaw allows code execution, and its bulletin does not list it as doing so.

Exploited before the fix

The crashes began on 2 October and the fixed builds arrived on 4 October. Citrix put out guidance on 2 October, but Beaumont wrote the following day that the support mitigations "don't appear to work," leaving administrators to block attackers' addresses at the firewall.

The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue on 4 October. Federal agencies have until 7 October, and the entry marks forensic triage as required. Whether the flaw has been used in ransomware is listed as unknown.

What to do now

First, check whether SAML is configured. If it is, install 14.1-73.41 or 13.1-64.28, or the matching FIPS build, even if the September update went on a few days ago. Then look for evidence of earlier attacks. Beaumont published log searches for crashes of the nsaaad authentication process and for the address above in /var/log/ns.log. Given his report of malware on a patched machine, treat a crash in those logs as a possible intrusion, not just an outage.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement